Senior Security GRC Lead
il y a 1 semaine
Description
Ant International strives to become the most trusted digital services connector to achieve sustainable growth of global commerce.
With a focus on Travel, Trade, Technology, and Talent, Ant International is committed to enhancing the digital mindset and capacities of businesses worldwide. Through fostering collaborative efforts with partners, we are driving responsible innovation and increase market accessibility for global SMEs.
In EMEA we do so across 3 key businesses: Alipay+, Antom and WorldFirst (Where you will partner as HRBP+ also).
Team Introduction:
We are seeking an experienced Senior Security GRC Lead to join our dynamic fintech team in Luxembourg. This critical role will be responsible for developing and maintaining our comprehensive information security governance, risk, and compliance framework in alignment with CSSF regulations, DORA requirements, and international standards. The successful candidate will play a pivotal role in ensuring our digital operational resilience and protecting our financial services infrastructure.
This position provides dedicated security governance support with a 50/50 split between:
- 50% supporting the EMEA regional team with security strategy, risk management, and security compliance initiatives
- 50% supporting the local Luxembourg entity with CSSF regulatory compliance, DORA implementation, and local security operations
- Develop and maintain the information security strategy, ensuring alignment with business objectives and regulatory requirements
- Establish and oversee the information security governance framework, including policies, standards, and procedures
- Lead the Information Security Committee and provide regular reporting to senior management
- DORA Compliance: Ensure full compliance with the Digital Operational Resilience Act (DORA) requirements, including ICT risk management, incident reporting, digital operational resilience testing, and third-party risk management
- CSSF Regulations: Maintain compliance with CSSF Circular 25/880 and other relevant Luxembourg financial regulations
- Industry Standards: Ensure adherence to PSD2-SCA, PCI-DSS, SWIFT CSP, ISO27001, and other applicable financial industry standards
- EBA (European Banking Authority) guidelines and technical standards
- Identify, assess, and prioritize security risks across the organization
- Develop and implement comprehensive risk mitigation strategies and action plans
- Conduct regular ICT risk assessments and oversee the annual Long Form Report preparation
- Implement and maintain a robust third-party vendor security risk management program
- Design and implement the DORA-compliant ICT risk management framework
- Plan and execute digital operational resilience testing programs, including threat-led penetration testing
- Establish and maintain incident response capabilities aligned with DORA incident reporting requirements
- Implement continuous security monitoring and threat detection capabilities
- Good understanding of Technology and Security architectural designs
- Good understanding of SIEM, DLP, Endpoint Security
- Oversee and deliver Security awareness and training programs
- Foster a security-conscious culture throughout the organization
- Provide security guidance and support to business units and technical teams
- Act as the primary contact point for IT security audits, inspections, and regulatory examinations
- Coordinate responses to regulatory inquiries and implement corrective actions
- Maintain relationships with CSSF and other regulatory authorities
- Experience: 5+ years in information security management roles as Security GRC Lead, or equivalent position in the financial services industry
- Technical Background: Strong technical foundation in cloud security, IT infrastructure, and application security
- Regulatory Expertise:
- DORA (Digital Operational Resilience Act) and its implementation requirements
- CSSF regulations, including Circular 25/880 on ICT security and risk management
- PSD2-SCA, PCI-DSS, SWIFT CSP, and other financial industry standards
- ISO27001 and NIST cybersecurity frameworks
- Cloud Security: Good background of Cloud Security controls and best practices
- Security Technologies: Good Knowledge of SIEM, EDR, vulnerability management, and identity management solutions
- Architecture: Understanding Security architectures
- Emerging Technologies: Knowledge of AI security.
- Leadership: Proven ability to lead security initiatives and influence stakeholders at all levels
- Communication: Excellent presentation and communication skills, with experience presenting to Risk Management Committees, Board of Directors, and regulatory bodies
- Problem-Solving: Strong analytical and decision-making abilities in complex regulatory environments
- Project Management: Experience managing security projects and compliance initiatives
-
Senior Cybersecurity Consultant
il y a 2 semaines
Luxembourg, Luxembourg SkillHubs Temps pleinJoin a global leader in Biopharma on a strategic cybersecurity program covering two production sites in Southern Europe.As Senior Cyber Security Consultant, you will work as an independent expert, supporting corporate and site security teams to strengthen the protection of OT, IT, and BMS systems in accordance with global governance and regulatory...
-
Senior Security Monitoring
il y a 2 semaines
Luxembourg, Luxembourg Arendt & Medernach Temps pleinArendt is your legal, tax and business services firm in Luxembourg.At Arendt we combine the entire value chain of services dedicated to asset managers, banks, insurers, public institutions, commercial companies and private clients operating in Luxembourg.Arendt offers specialist advice, that encompasses all legal, regulatory, taxation and advisory aspects of...
-
Senior Security Officer
il y a 2 semaines
Luxembourg, Luxembourg RTL Group BCE Temps pleinBroadcasting Center Europe (BCE) is a European leader in media services, system integration and software development in the areas of television, radio, production and postproduction, telecommunication and IT.With its extensive experience on the media market, our team provides high-quality services, supporting our customers in their development.With more than...
-
Information Security, Senior Officer
il y a 1 semaine
Luxembourg, Luxembourg Arendt Temps pleinArendt & Medernach is the leading independent business law firm in Luxembourg with over 800 professionals. The firm's international team of more than 450 legal experts represents Luxembourg and foreign clients in all areas of Luxembourg business law from its main office in Luxembourg and representative offices in Frankfurt, Hong Kong, London, New York, and...
-
Chief Information Security Officer
il y a 2 semaines
Luxembourg, Luxembourg Julius Baer Temps pleinAt Julius Baer, we celebrate and value the individual qualities you bring, enabling you to be impactful, to be entrepreneurial, to be empowered, and to create value beyond wealth. Let's shape the future of wealth management together. The CISO Europe Hub is a senior leadership role responsible for defining and executing the regional Information & Cyber...
-
System & Security Technical Lead
il y a 2 semaines
Luxembourg, Luxembourg TMC Temps pleinLuxembourg Digital & IT Luxembourg, Luxembourg HybridTMC Luxembourg is looking for a System and Security Technical Lead (M/F) for one of its clients.About The Member CompanyWe are a global high-tech consultancy company with a team of entrepreneurial engineers, scientists, and digital experts from around the world. Together we form a fast-growing and proud...
-
Einen IT/OT Netzwerk-&Security Ingenieur
il y a 2 semaines
Luxembourg, Luxembourg SEO (Société Electrique de l'Our) Temps pleinDie Société Electrique de l'Our (SEO) betreibt das Pumpspeicherkraftwerk in Vianden, das ein integraler Bestandteil des europäischen Verbundsystems ist. Das Kraftwerk leistet einen bedeutenden Beitrag zur Leistungs- und Frequenzregelung sowie zur Spannungsstabilisierung im europäischen Stromnetz. Dank seiner hohen Verfügbarkeit stellt es zudem eine...
-
Senior Sales Lead
il y a 1 semaine
Luxembourg, Luxembourg Deutsche Börse Group Temps pleinYour area of workAs part of the Eurex Sales team, you will play a key role in driving client engagement and revenue growth across a broad range of asset classes, including equity index derivatives, repo, fixed income, and OTC interest rate derivatives. This sales role is focused on building and deepening strategic client relationships, identifying new...
-
Security Manager
il y a 2 semaines
Luxembourg, Luxembourg Pinkerton Temps pleinOverview170+ Years Strong. Industry Leader. Global Impact.At Pinkerton, the mission is to protect our clients. To do this, we provide enterprise risk management services and programs specifically designed for each client. Pinkerton employees are one of our most important assets and critical to the delivery of world-class solutions. Bonded together, we share...
-
Security Testing Specialist
il y a 7 jours
Luxembourg, Luxembourg Qualco Temps pleinAt Quento, the ICT arm of the Qualco Group, we deliver comprehensive and innovative solutions across AI, Digital Engineering, Cloud, and Cybersecurity, helping businesses accelerate digital transformation. With a presence in Greece, Luxembourg, and Belgium, and backed by the expertise of the Qualco Group, we combine deep technical knowledge with strategic...